From the perspective of a senior cloud security audit practitioner in an organization of a mature security program with cloud adoption, which of the following statements BEST describes the DevSecOps concept?

From the perspective of a senior cloud security audit practitioner in an organization of a mature security program with cloud adoption, which of the following statements BEST describes the DevSecOps concept?A . Process of security integration using automation in software developmentB . Development standards for addressing integration, testing, and deployment...

December 11, 2021 No Comments READ MORE +

Which of the following controls BEST matches this control description?

Policies and procedures shall be established, and supporting business processes and technical measures implemented, for maintenance of several items ensuring continuity and availability of operations and support personnel. Which of the following controls BEST matches this control description?A . Operations MaintenanceB . System Development MaintenanceC . Equipment MaintenanceD . System...

December 10, 2021 No Comments READ MORE +

A CSP providing cloud services currently being used by the United States federal government should obtain which of the following to assure compliance to stringent government standards?

A CSP providing cloud services currently being used by the United States federal government should obtain which of the following to assure compliance to stringent government standards?A . Multi-Tier Cloud Security (MTCS) AttestationB . FedRAMP AuthorizationC . ISO/IEC 27001:2013 CertificationD . CSA STAR Level CertificateView AnswerAnswer: B Explanation: Reference: https://www.ftptoday.com/blog/benefits-using-fedramp-authorized-cloud-service-provider

December 9, 2021 No Comments READ MORE +

Which of the following CSP activities requires a client’s approval?

Which of the following CSP activities requires a client’s approval?A . Delete the guest account or test accountsB . Delete the master account or subscription owner accountsC . Delete the guest account or destroy test dataD . Delete the test accounts or destroy test dataView AnswerAnswer: D

December 9, 2021 No Comments READ MORE +

Customer management interface, if compromised over public internet, can lead to:

Customer management interface, if compromised over public internet, can lead to:A . customer’s computing and data compromise.B . access to the RAM of neighboring cloud computer.C . ease of acquisition of cloud services.D . incomplete wiping of the data.View AnswerAnswer: A

December 9, 2021 No Comments READ MORE +

A cloud customer configured and developed a solution on top of the certified cloud services. Building on top of a compliant CSP:

A cloud customer configured and developed a solution on top of the certified cloud services. Building on top of a compliant CSP:A . means that the cloud customer is also compliant.B . means that the cloud customer and client are both compliant.C . means that the cloud customer is compliant...

December 8, 2021 No Comments READ MORE +

Which of the following quantitative measures is KEY for an auditor to review when assessing the implementation of continuous auditing of performance on a cloud system?

Which of the following quantitative measures is KEY for an auditor to review when assessing the implementation of continuous auditing of performance on a cloud system?A . Service Level Objective (SLO)B . Recovery Point Objectives (RPO)C . Service Level Agreement (SLA)D . Recovery Time Objectives (RTO)View AnswerAnswer: C

December 7, 2021 No Comments READ MORE +

Which of the following metrics are frequently immature?

Which of the following metrics are frequently immature?A . Metrics around Infrastructure as a Service (IaaS) storage and network environmentsB . Metrics around Platform as a Service (PaaS) development environmentsC . Metrics around Infrastructure as a Service (IaaS) computing environmentsD . Metrics around specific Software as a Service (SaaS) application...

December 6, 2021 No Comments READ MORE +

Which of the following attestation allows for immediate adoption of the Cloud Control Matrix (CCM) as additional criteria to AICPA Trust Service Criteria and provides the flexibility to update the criteria as technology and market requirements change?

Which of the following attestation allows for immediate adoption of the Cloud Control Matrix (CCM) as additional criteria to AICPA Trust Service Criteria and provides the flexibility to update the criteria as technology and market requirements change?A . PC-IDSSB . CSA STAR AttestationC . MTCSD . BSI Criteria Catalogue C5View...

December 6, 2021 No Comments READ MORE +

Which of the following BEST ensures adequate restriction on the number of people who can access the pipeline production environment?

Which of the following BEST ensures adequate restriction on the number of people who can access the pipeline production environment?A . Ensuring segregation of duties in the production and development pipelines.B . Role-based access controls in the production and development pipelines.C . Separation of production and development pipelines.D . Periodic...

December 6, 2021 No Comments READ MORE +